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REMARKS/ARGUMENTS 



Claims 1 through 20 are pending in this application. Claims 1 through 19 stand rejected 
under 35 U.S.C. § 102(e) as allegedly being anticipated by U.S. Patent Publication 
2002/0038357 Al (Haverstock et al.). Claim 20 stands rejected under 35 U.S.C. § 103(a) as 
allegedly being unpatentable over Haverstock et al. in view of U.S. Patent 5,555,375 (Sudama). 
Applicants' undersigned representative respectfully requests reconsideration of the rejections in 
light of the following remarks. 



Applicants' have noted 

[a] particularly important operation in workflow systems is 
managing access to documents as they move through various 
stages of a workflow. In a typical document-publishing scenario, 
significant time can elapse between creation of a document and 
final approval of the document for external viewing or publishing. 
For example, after an author revises an existing document and 
enters the revised document into a publishing workflow, several 
editors may need to review the document prior to the document 
receiving final approval for viewing by people outside the 
publishing group. It may take an extended period before the 
editors have an opportunity to review the document. In the 
meantime, it is necessary to restrict access to the revised document 
until it receives final approval. Indeed, it is necessary to restrict 
access to the document even if the editing process takes only short 
time. Editors should be given access to the new version of the 
document for purposes of editing and approving the document 
while those without approval authority should be given access 
to the original version of the document without revisions. 
Thus, it can be said that the original or "base" document and 
the revised document should be maintained separately, or 
"isolated" from each other and access given as appropriate to 
one or the other during the period that the document is 
undergoing approval in the publishing workflow. 



Prior Art Rejections 



Applicants' have disclosed systems and methods to provide such functionality. 
According to an aspect of the disclosed systems and methods, 
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- when a revision is made to an original or "base" document and 
the revision placed in a workflow, a separate "working" copy 
of the base document is generated. As the document moves 
through the workflow, new versions of the "working" copy 
document may also be generated. Security controls, which define 
who may access the base document as well as any versions of the 
working copy document, are defined and stored in relation to the 
documents. The security controls further define the types of 
actions users may take with respect to the document. For example, 
the security controls may specify that a user should be given 
access to the working copy document as opposed to the base 
document and should have the capability to check-out the working 
copy of the document for revision. 

Accordingly, Applicants' claim 1 is directed to a computer-implemented method for 
controlling access to documents during a workflow, comprising: 



upon entry of a base document into a workflow, 
creating a working copy of the base document; 

selectively providing a user access to either the base 
document or the working copy of the base document 
depending upon the identity of a user; and 

selectively providing access to perform operations on the 
working copy of the base document depending upon the identity of 
a user. 



In order for a reference to anticipate claim 1, the reference must teach all of the claimed 
elements, including creating a working copy of the base document upon entry of a base 
document into a workflow, and selectively providing a user access to either the base 
document or the working copy of the base document depending upon the identity of a user. 

Applicants' undersigned representative respectfully suggests that the Haverstock et al. neither 
teach nor even suggest the emphasized claim elements. 

Claim 13 is directed to a system for providing document isolation in a workflow 
environment comprising: 



a processor, wherein said processor is operable to execute 
instructions for performing the following acts: 

maintaining for a base document undergoing a 
publishing workflow, a copy of the base document; 
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maintaining access control data in relation to the base 
document and the copy of the base document; and 

upon receipt of a request to access the base document, 
selectively determining based on the access control data to 
provide access to either the base document or the copy of the 
base document. 



In order for a reference to anticipate claim 13, the reference must teach each of the claimed 
elements, including maintaining a copy of a base document undergoing a publishing 
workflow, and upon receipt of a request to access the base document, selectively 
determining based on the access control data to provide access to either the base document 
or the copy of the base document . Applicants' undersigned representative respectfully 
suggests that Haverstock et al. does not teach or even suggest the emphasized claim elements. 

Haverstock et al. allege to disclose a system for enabling access to non-HTML files from 
a Web browser. (Abstract). When a system user requests a non-HTML file from a database 
using a Web browser, the Web browser transmits the request to a server via an HTTP server and 
module. (Abstract). The server locates the requested document, retrieves it, and translates the 
document into a format supported by the Web browser. (Abstract). The translated document is 
then communicated to the Web browser. (Abstract). Haverstock et al. further disclose restricting 
access to fields and employs the concept of roles in doing so. (fflf 57, 65.) For example, a user 
with the "depositor" role can write to a database, (paragraph 68.) A user with the "reader" role 
has read-only access to pages on the Web site, (paragraph 69.) An "author" can create and post 
new pages to the Web site, (paragraph 70.) 

Contrary to the Examiner's assertion, however, Haverstock et al. do not disclose or even 
suggest creating a copy of a base document upon creation of a workflow, and selectively 
providing a user access to either the base document or the copy of the base document 
depending upon the identity of the user . Rather, in the system disclosed by Haverstock et al., 
a user is always given access to one document - the document that has been translated for 
distribution by the Web browser. (Abstract.) Haverstock et al. do not disclose or even suggest 
that a user selectively be given access to either the base document or a copy of the base 
document depending on the identity of the user, as required by the claims. While Haverstock 
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et al.-disclose using "roles" to control access to data, they do not teach" or in any way suggest 
selectively providing a user access to either the base document or the copy of the base 
document depending upon the identity of the user. Indeed, the Examiner's remarks in his 
"Response to Arguments" that Haverstock et al teach "selectively providing a user access to the 
working copy of the [sic] based document depending upon the identity of the user" misses the 
point - the claims require selectively providing a user access to either the base document or 
the working copy of the base document depending upon the identity of a user. Haverstock 
et al. do not teach or suggest this claim limitation. Accordingly, Applicants' undersigned 
representative respectfully requests that the rejection be withdrawn. If the Examiner maintains 
the rejection, Applicants' undersigned representative respectfully requests that in order to 
facilitate examination of the claims, the Examiner not only identify paragraph numbers, but 
quote the specific language in the reference that is alleged to teach each element of each claim. 

Claim 20 Is Non-Obvious 

Claim 20 is directed to 



[a] method of updating access controls to reflect the addition of a 
new operation that may be performed on a copy of a base 
document, in a system wherein access to operations to be 
performed on a copy of the base document are controled using an 
access control list which identifies the operations that may be 
performed and the roles that a user must have to access those 
operations, comprising: 

assigning a unique identifier to the new operation that 
may be performed on a copy of a base document ; 

updating the access control list to include an entry for 
the unique identifier for the new operation; and 

updating the access control list to include an entry 
identifying the roles that have access to the new operation. 



In order for a reference or set of references to render claim 20 obvious, the references must teach 
all of the elements and must also teach combining the elements in the claimed combination. 
Applicants' undersigned representative respectfully suggests that the cited references do not even 
teach all of the claim limitations, and therefore can not possibly suggest combining the 
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limitations as required by claim 20; Accordingly, it" is notpossible that the cited references 
render claim 20 obvious. 

The Examiner admits that Haverstock et al. entirely fail to teach assigning a unique 
identifier to the new operation that may be performed on a copy of a base document, updating 
the access control list to include an entry for the unique identifier corresponding to the new 
operation, and updating the access control list to include an entry identifying the roles that have 
access to the new operation. (Office Action, 23-24.) However, the Examiner alleges that 
Sudama either teaches or renders these claim elements obvious. Applicants' undersigned 
representative respectfully disagrees. 

Sudama alleges to disclose a method and apparatus for administering an operation 
specified for performance on a set of independently managed hosts. (Abstract.) The operation is 
transferred to a management server designated by the system to administer the operation 
specified on the group object. The designated management server thereafter decomposes the 
group object into constituent objects which may be host objects or additional group objects. 
(Abstract.) The decomposition continues until all group objects are decomposed into host 
objects, and the host objects are executed on various servers. After executing the operations, the 
host objects and group objects return status information back to the designated management 
server. (Abstract.) Ultimately, the status information is transmitted to the management server 
that initially received the operation. (Abstract.) 

Sudama further teaches assigning operation identifiers to objects and group objects that 
are created during the decomposition of the original object. (Col. 8, 11. 55-57.) These identifiers 
are used to facilitate the return of status information to the parent object. (Col. 8, 11. 61-63.) 
Thus, Sudama teaches assigning identifiers to sub-operations in order to track the operations and 
to facilitate return of status information. This is in contrast to claim 20, which specifies 
assigning unique identifiers to new operations that may be performed on a copy of base 
document and updating an access control list to include an entry identifying roles that have 
access to the new operation. In truth, Sudama nowhere suggests that unique identifiers be 
associated with new operations that may be performed on a copy of a base document, and 
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updating an access control list to limit the roles that have access to the operation. 

Workflow documents and controlling access to operations performed on those documents is 
simply not a consideration raised by Sudama. Rather, in Sudama the unique identifiers 
are generated for an entirely different purpose - to facilitate the return of status 
information regarding computer processes. Accordingly, the Examiner's assertion that 
updating the access control list is "essential" to Sudama, is not supported by the text of the 
reference or by logic. 

The Examiner in his "Response to Arguments" admits that several elements of claim 20 
are not taught by Sudama, and therefore the Examiner relies upon impermissible hindsight to 
support the allegation that the claim would have been obvious. Indeed, the Examiner admits that 
"Haverstock and Sudama did not specifically [teach] updating the access control list step to 
include an entry for the unique identifier for the new operation or to include an entry identifying 
the roles that have access to the new operation." (Office Action, Para. 28.) Nevertheless, the 
Examiner alleges "in order to add the new operation and enable the roles to have access to the 
new operation, it would have been obvious that the access control list must be updated so the 
authentication to the exiting users is valid with the new operation since the access control list is 
in correspondence with the operations and user roles." (Id.) Thus, the rejection is based not on 
the teachings of the reference, but rather upon impermissible hindsight by the Examiner. See 
MPEP § 2145. In truth, Sudama does not teach the claim elements that the Examiner attributes 
to it. For this reason alone the rejection must be withdrawn. 

Furthermore, in order to establish a prima facie case of obviousness, there must be some 
suggestion or motivation, either in the references themselves or in the knowledge generally 
available to one of ordinary skill in the art, to modify the reference or to combine reference 
teachings. MPEP § 2143. The teaching or suggestion to make the claimed combination and the 
reasonable expectation of success must both be found in the reference, and not based on 
applicant's disclosure. MPEP § 2143 citing In re Vaeck, 947 F.2d 488, 20 USPQ2d 1438 (Fed. 
Cir. 1991). Even if Sudama taught the claimed elements, which the Examiner admits it does not, 
there is no suggestion in Sudama that its teachings should or could be used in another system, 
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and more particularly one such" as taught - by Haverstock et al. Indeed, there is no teaching by 
Sudama that the system it discloses are suitable and useful in other systems such as a workflow 
control system. 

Therefore, because they entirely fail to teach or even suggest the elements of claim 20, 
Haverstock et al. and Sudama et al can not possibly render claim 20 obvious. Withdrawal of the 
rejection is respectfully requested. Furthermore, if the Examiner maintains the rejection, 
Applicants' undersigned representative respectfully requests that the Examiner quote the specific 
language in Sudama that allegedly teach each claim element, and the specific language in 
Sudama that allegedly suggest combining those claim elements with specific teachings in 
Haverstock et al. arrive at the combination of claim 20. 



Applicants' undersigned representative respectfully submits that all of the claims 
patentably define over the prior art of record. Reconsideration of the present Office Action and a 
Notice of Allowance are respectfully requested. 



Woodcock Washburn LLP 
One Liberty Place - 46th Floor 
Philadelphia PA 19103 
Telephone: (215)568-3100 
Facsimile: (215) 568-3439 



CONCLUSION 



Date: March 23, 2004 




KenneflrfC Eifernlaft^ 
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